MidnightBSD

Advisories for auracms

CVE-2010-4774 HIGH

SQL injection vulnerability in pdf.php in AuraCMS 1.62 allows remote attackers to execute arbitrary SQL commands via the id parameter, a different vector than CVE-2007-4804 and CVE-2007-4171.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-89,

Products Affected

Vendor Product Version
auracms auracms 1.62
CVE-2014-1401 MEDIUM

Multiple SQL injection vulnerabilities in AuraCMS 2.3 and earlier allow remote authenticated users to execute arbitrary SQL commands via the (1) search parameter to mod/content/content.php or (2) CLIENT_IP, (3) X_FORWARDED_FOR, (4) X_FORWARDED, (5) FORWARDED_FOR, or (6) FORWARDED HTTP header to index.php.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-89,

Products Affected

Vendor Product Version
auracms auracms 2.2.2
auracms auracms 1.3
auracms auracms 1.1
auracms auracms 1.2
auracms auracms 1.62
auracms auracms 2.0
auracms auracms 2.2.1
auracms auracms 1.5
auracms auracms 1.61
auracms auracms 2.2
auracms auracms 1.0
auracms auracms *
auracms auracms 2.1
CVE-2014-3974 MEDIUM

Cross-site scripting (XSS) vulnerability in filemanager.php in AuraCMS 3.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the viewdir parameter.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-79,

Products Affected

Vendor Product Version
auracms auracms *
CVE-2014-3975 MEDIUM

Absolute path traversal vulnerability in filemanager.php in AuraCMS 3.0 allows remote attackers to list a directory via a full pathname in the viewdir parameter.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-22,

Products Affected

Vendor Product Version
auracms auracms 3.0
CVE-2018-15199 LOW

AuraCMS 2.3 allows XSS via a Bukutamu -> AddGuestbook action.

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
auracms auracms 2.3
CVE-2018-16338 MEDIUM

An issue was discovered in AuraCMS 2.3. There is a CSRF vulnerability that can change the administrator's password via admin.php?mod=users and subsequently add a page or menu, or submit a topic.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-352,

Products Affected

Vendor Product Version
auracms auracms 2.3